Signs your WordPress site has been hacked
- Visitors get sent to a spam, gambling or fake pharmacy site.
- Chrome or Google shows a red warning such as "Dangerous site" or "Deceptive site ahead".
- Google search results show pages you never created, often full of spam keywords or written in Japanese.
- You can't log in, or there are admin users you don't recognise.
- Your host has suspended the site or emailed you about malware.
- The site has suddenly slowed down, or your traffic has dropped for no clear reason.
Most WordPress hacks aren't personal. Bots scan millions of sites for outdated plugins, themes and weak passwords, and small business sites are easy targets because nobody is watching them day to day. The good news: a hacked WordPress site can usually be cleaned up without starting over.
What to do right now
- Don't delete the website. Deleting files or the whole site can destroy your content along with the evidence of how the attackers got in.
- Change your passwords. Change your hosting account, WordPress admin and FTP/SFTP passwords, plus your email if it uses the same password. Do it from a computer you trust.
- Tell your host. They may already have malware scan results and backups, and can often tell you when the problem started.
- Find your latest backup, but don't restore it blindly. The backup may contain the same malware, and restoring it doesn't close the hole the attackers used. They'll often come straight back.
- Write down what you've seen. Note when it started, take screenshots of any warnings, and keep any emails from your host or Google.
Then get help. The longer malware stays on your site, the more damage it does to your Google rankings and your customers' trust.
How I clean up a hacked WordPress site
- Back up the site exactly as it is. Nothing gets lost, even the infected version, so we can always go back.
- Find the malware. I check WordPress core files, your theme, plugins and database for injected code, hidden backdoors and spam pages.
- Remove it and replace infected files. WordPress core, plugins and themes are swapped for clean copies, and admin users that shouldn't exist are removed.
- Close the way in. The outdated plugin, theme or weak login the attackers used gets updated, replaced or locked down, and passwords and security keys are reset.
- Clear the Google warning. Once the site is clean, I request a review in Google Search Console, and set it up for you if you don't have it yet. Google makes the final call, and reviews usually take a few days.
- Keep it clean. Updates, backups and monitoring get set up so it doesn't happen again, either for you to run or as ongoing maintenance with me.
Why work with me
- I've worked with WordPress since 2010, and malware fixes and site migrations were a regular part of my long-term work with a US design agency.
- I build monitoring tools, including a dashboard that watches 32 client WordPress sites for downtime, visual changes and pending updates.
- Elementor is my main page builder, so Elementor sites aren't a problem.
- I'm 2 hours behind Brisbane and 2–3 hours behind Sydney and Melbourne, so you're not waiting overnight for answers.
See my sample websites and work history.
Frequently asked questions
How did my WordPress site get hacked?
Most often through an outdated plugin or theme with a known security hole, a weak or reused password, or a pirated ("nulled") premium plugin. Automated bots scan for these around the clock, so it usually isn't personal.
Will I lose my website content?
Usually not. I back up the site exactly as it is before touching anything, and the cleanup removes the malicious code, not your pages, posts or products.
Do I need a new website?
Usually not. A rebuild only makes sense if the site is very old or too damaged to repair, and I'll tell you honestly if that's the case.
Can I just restore an old backup?
You can, but the backup may contain the same malware, and if the way the attackers got in is still open, they'll usually be back within days.
Will the Google warning go away?
Once the site is clean, I request a review in Google Search Console. Google decides when to remove the warning, and reviews usually take a few days.
How long does a cleanup take?
It depends on how badly the site is infected and how big it is. I'll look at the site first and give you an estimate before I start.
How much does it cost?
I'll quote you before I start, once I've had a look at the site and know how much work is involved.
Do you work with Elementor and WooCommerce sites?
Yes. Elementor is my main page builder, and I've built and maintained WooCommerce stores.